Seems AI Powered Vulnerability Discovery Is Over Hyped

Seems AI Powered Vulnerability Discovery Is Over Hyped

As Is Tradition

Anthropic would have you believe that the power of Claude Mythos and Project Glasswing have to detect unpatched vulnerabilities is so great that it should never be made publicly available.  They have suggested that doom would follow as nefarious programmers would take advantage of the fertile new field of vulnerabilities.  Well, those that were given access to the closed Mythos model and Project Glasswing have been finding vulnerabilities, but not ones which are realistically exploitable.

VulnCheck and the Berkeley Vulnerability Research Initiative took a look at 1,061 publicly attributed AI-assisted vulnerability discoveries, as in vulnerabilities that have been made publicly available, and a whopping 14 vulnerabilities have been confirmed as exploited in the wild.  That monstrous 1.3% is essentially the exact same percentage of active exploits as boring old human discovered vulnerabilities.  It seems that while Project Glasswing can find these vulnerabilities faster than a human it’s no more effective than we are.

That’s not to say there is no danger in AI powered vulnerability testing, as OpenAI and Hugging Face found out.  There are more details on what happened in that specific example below.

Source link

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply

Your email address will not be published. Required fields are marked *